3 ms·
I do wish this wasn't a sponsored ad masquerading as an engineering blog until the last paragraph, but yes, these things are extremely challenging. What people
by sullivanmatt 4y ago
I do wish this wasn't a sponsored ad masquerading as an engineering blog until the last paragraph, but yes, these things are extremely challenging. What people miss is that the big cost isn't building or integrating these things, it's supporting them. I was the IAM features product manager for a mid-market B2B SaaS and had to jump on calls multiple times a week to help our Fortune 500 client base with planning our their deployment of directory integration (SCIM). You would think you could train support staff for the task, but with each IdP having its own zany behaviors and nuances (or just not following the protocols at all, cough Azure AD), you end up needing to pay someone who is extraordinarily technical to be an absolute authority in how these things work and are managed at both ends of the connection. I was backstopped by two other support engineers who could help with the day-to-day and escalated to me as needed. So multiple staff level engineers, all just to support two identity related features (SSO, SCIM) for one mid-market SaaS.
Everyone likes to gripe (including here in this thread!) about B2B charging for Enterprise features like SSO, but withhold your judgement until you've actually lived through supporting it. The burden of helping a company like Meta integrate their weird, bespoke, homegrown identity solution into your business app could literally cost your business tens of thousands of dollars per year (and no, that's not a made up example).
- caloique 4y agoIndeed, people forget about the cost and pain of supporting these things. For full disclosure, I am a co-founder @BoxyHQ, an open source devtools startup providing free enterprise SSO (called SAML Jackson), directory sync (beta - feedback is welcome), audit logs and so on. Pricing is tricky, and as you said, people complain a lot. Since this is because we all have different points of view, we will never agree. But there are some things that most of us should agree, like the fact that we need to raise the security standards. Then the question is what we can do as a community - besides trying to avoid being on the sso.tax list.
- grinich 4y ago(I work at WorkOS.) This comment pretty much exactly describes why we're building WorkOS. Developing enterprise features yourself in-house is super time consuming and ends up being a huge drag on product development. We essentially want to provide "Stripe for enterprise features" so developers don't need to do this repeated work. It's a surprisingly complex problem. We've been working on it for over 3 years[0] and still have a ton more work to do. This is not something you can hack together in a few months or solve with an open source package. Thankfully we are really well funded[1] with a long runway and hundreds of customers. It also doesn't stop with SSO and SCIM. You end up needing of other stuff including authorization, permissions, encryption, compliance, and audit logs (which incidentally we launched today[2]). [0] https://news.ycombinator.com/item?id=22607402 https://news.ycombinator.com/item?id=22607402 [1] https://workos.com/blog/series-b https://workos.com/blog/series-b [2] https://workos.com/audit-logs https://workos.com/audit-logs (As a total aside, I agree it's not very clear this blog post is sponsored content. Will see if we can get the StackOverflow editorial team to make it more clear. We just wanted to use our marketing budget to ship something genuinely useful. ;))